The Vigil@nce team watches public vulnerabilities impacting your computers, and then offers security solutions, a vigilance database and tools to fix them.

Computer vulnerabilities of IBM Notes

Apache Log4j 1.2: code execution via Socket Server Deserialization
An attacker can use a vulnerability via Socket Server Deserialization of Apache Log4j 1.2, in order to run code...
6198380, 6371652, cpuapr2020, cpujul2020, CVE-2019-17571, DLA-2065-1, DSA-4686-1, KB0085481, NTAP-20200110-0001, openSUSE-SU-2020:0051-1, SUSE-SU-2020:0053-1, SUSE-SU-2020:0054-1, SUSE-SU-2020:14267-1, USN-4495-1, VIGILANCE-VUL-31193
Codehaus: code execution via Deserialization
An attacker can use a vulnerability via Deserialization of Codehaus, in order to run code...
6198380, CVE-2019-10202, KB0085481, RHSA-2019:2935-01, RHSA-2019:2936-01, RHSA-2019:2937-01, RHSA-2019:2938-01, VIGILANCE-VUL-30483
Spring Security: privilege escalation via PlaintextPasswordEncoder Null Encoded Password
An attacker can bypass restrictions via PlaintextPasswordEncoder Null Encoded Password of Spring Security, in order to escalate his privileges...
5048, CVE-2019-11272, DLA-1848-1, KB0085481, VIGILANCE-VUL-29711
jackson-databind: file reading
An attacker can read a file from a client using jackson-databind, in order to obtain sensitive information...
5048, cpujan2020, cpujul2019, cpuoct2019, CVE-2019-12086, DLA-1798-1, DSA-4452-1, FEDORA-2019-ae6a703b8f, FEDORA-2019-fb23eccc03, KB0085481, RHSA-2019:2935-01, RHSA-2019:2936-01, RHSA-2019:2937-01, RHSA-2019:2938-01, RHSA-2019:3044-01, RHSA-2019:3045-01, RHSA-2019:3046-01, RHSA-2019:3050-01, VIGILANCE-VUL-29375
jackson-datatype-jsr310: denial of service via Input Validation
An attacker can trigger a fatal error via Input Validation of jackson-datatype-jsr310, in order to trigger a denial of service...
cpuoct2019, CVE-2018-1000873, FEDORA-2019-df57551f6d, KB0085481, VIGILANCE-VUL-28552
libpng: memory leak via png_create_info_struct
An attacker can create a memory leak via png_create_info_struct() of libpng, in order to trigger a denial of service...
269, cpujul2019, CVE-2019-6129, DSA-2020-198, FEDORA-2019-5c794ec7ba, FEDORA-2019-a5ec38072a, KB0088721, VIGILANCE-VUL-28269
IBM Notes/Domino: code execution via NSD Shared Memory IPC
An attacker can use a vulnerability via NSD Shared Memory IPC of IBM Notes/Domino, in order to run code...
CVE-2018-1171-ERROR, CVE-2018-1771, ibm10743405, VIGILANCE-VUL-28033
IBM Java: code execution via Attach API
An attacker can use a vulnerability via Attach API of IBM Java, in order to run code...
CERTFR-2018-AVI-544, CVE-2018-12539, ibm10725491, ibm10729349, ibm10730083, ibm10733905, ibm10735319, ibm10735325, ibm10738401, ibm10738997, ibm10742729, ibm10743193, ibm10743351, RHSA-2018:2568-01, RHSA-2018:2569-01, RHSA-2018:2575-01, RHSA-2018:2576-01, SUSE-SU-2018:2574-1, SUSE-SU-2018:2583-1, SUSE-SU-2018:2649-1, SUSE-SU-2018:2839-1, SUSE-SU-2018:3082-1, VIGILANCE-VUL-27093
IBM Java: directory traversal via DTFJ
An attacker can traverse directories via DTFJ of IBM Java, in order to read a file outside the service root path...
CERTFR-2018-AVI-544, CVE-2018-1656, ibm10725491, ibm10729349, ibm10730083, ibm10733905, ibm10735319, ibm10735325, ibm10738401, ibm10738997, ibm10742729, ibm10743193, ibm10743351, RHSA-2018:2568-01, RHSA-2018:2569-01, RHSA-2018:2575-01, RHSA-2018:2576-01, SUSE-SU-2018:2574-1, SUSE-SU-2018:2583-1, SUSE-SU-2018:2649-1, SUSE-SU-2018:2839-1, SUSE-SU-2018:3082-1, VIGILANCE-VUL-27092
IBM Java: denial of service via java.math
An attacker can generate a fatal error via java.math of IBM Java, in order to trigger a denial of service...
CVE-2018-1517, ibm10738401, ibm10742729, ibm10743351, RHSA-2018:2568-01, RHSA-2018:2569-01, RHSA-2018:2575-01, RHSA-2018:2576-01, SUSE-SU-2018:2574-1, SUSE-SU-2018:2583-1, SUSE-SU-2018:2649-1, SUSE-SU-2018:2839-1, SUSE-SU-2018:3082-1, VIGILANCE-VUL-27091
Our database contains other pages. You can request a free trial to read them.